Barracuda - Managed XDR
This fully managed, next-generation solution, powered by Barracuda’s 24/7/365 global security operations center (SOC), leverages advanced AI analytics and threat intelligence to prevent breaches before they impact your organization. As an open XDR platform, it integrates seamlessly with your existing tools, boosts operational efficiency and delivers true defense-in-depth
Features
- 24/7/365 global Security Operations Centre staffed by five specialized teams
- Enterprise-grade threat intel
- Unlimited log ingestion & processing of security telemetry
- AI-driven Detection and Automated Threat Response (ATR)
- Managed Endpoint Protection
- Managed Vulnerability Security
- Cloud & Email detection & incident response
- Network & Server detection & Incident Response
- Open XDR platform integrating with your environment
- SIEM log search & visibility
Benefits
- Security Operations Centre powered protection, around the clock
- Protection across entire attack lifecycle, delivering defense-in-depth
- Built to scale, ingesting trillions of telemetry signals
- Identify true positives amidst the noise,
- Reducing time to respond (TTR) to seconds
- real-time threat detection and response without human intervention
- Helps you meet evolving regulatory & compliance standards
- instantly extends your capabilities, eliminating coverage gaps, reducing alert noise
- unified dashboard — complete oversight across your entire security ecosystem
- Coverage for Endoint, Network, Cloud, Email, Server & Vulnerabilty assessment
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 7 7 1 6 6 8 6 1 2 4 4 0 6 8
Contact
PRIMESYS LTD
Ryan Smith
Telephone: 07866813062
Email: info@primesys.co.uk
About your service
- Service categories
-
Applications
Production and operations
- Other operations
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- Supported vendor technology defined by supported intergrations list
- System requirements
-
- Device license required (Endpoint)
- User license required (cloud & Email)
- Server license required (Server)
- Network license Required (Network & Firewall)
- IP license Required (Vulnerability Security)
User support
- Email or online ticketing support
- Yes
- Support response times
-
Enhanced support is included with all services. Upgraded support can be purchased
https://www.barracuda.com/support/plans-and-packages - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- None or don’t know
- How the web chat support is accessible
- Web chat is accesible via main Barrauda Website, Support Portal and from within product service
- Web chat accessibility testing
- None
- Onsite support
- No
- Support levels
-
All Barracuda SaaS software comes with 24x7x365 support services included with the service. Premium support can be purchased at additional cost
https://assets.barracuda.com/assets/docs/dms/Barracuda_Premium_Support.pdf - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
- All Barracuda customer have access to Barracuda Campus which documents both how to use the system and gives access to self paced video training. Customer may also purchase Professional Services direct from Barracuda to support installation and delivery of the solution. Professional Services are an additional cost.
- Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- For each of the components of the Service for which the Customer purchases a subscription, Barracuda collects and maintains the security logs for a rolling 90-day period solely for Barracuda’s use to deliver the Service. These security logs are not available to Customer for download or through the XDR dashboard. The Service does not collect any end customer data other than security log data. Any information regarding the end customer in the dashboard will automatically be deleted when the Customer’s subscription expires. Barracuda will retain any security alerts for 15 months after a customer subscription expires.
- End-of-contract process
- For each of the components of the Service for which the Customer purchases a subscription, Barracuda collects and maintains the security logs for a rolling 90-day period solely for Barracuda’s use to deliver the Service. These security logs are not available to Customer for download or through the XDR dashboard. The Service does not collect any end customer data other than security log data. Any information regarding the end customer in the dashboard will automatically be deleted when the Customer’s subscription expires. Barracuda will retain any security alerts for 15 months after a customer subscription expires.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- See Barracuda T&C's https://www.barracuda.com/company/legal
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Platform will work with any browser however recommended to be used via desktop for clarity and ease of use.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- Interface is web based and allows for resellers and customers to support environments
- Accessibility standards
- None or don’t know
- Description of accessibility
- Barracuda services are designed to work with accessible features of the web browser.
- Accessibility testing
- None
- API
- No
- Customisation available
- Yes
- Description of customisation
- Customers can make amendments to policies for endpoint protection including USB block policies and file path exclusions.
Scaling
- Independence of resources
-
Barracuda Managed XDR is designed and built with a highly resilient and sclable cloud architecture that will expand upon demand increase. This is all backed by a published SLA of which further details can be found here:
https://assets.barracuda.com/assets/docs/dms/Barracuda_Managed_XDR_Service_Description.pdf
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Activity logs
Summary Reports
Realtime Dashboards
Audit Logs - Reporting types
-
- Real-time dashboards
- Regular reports
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller (no extras)
- Organisation whose services are being resold
- Barracuda Networks
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Supplier-defined controls
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Other
- Other data at rest protection approach
- Log and configuration data that is held in the Service is encrypted during transmission and at rest.
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- For each of the components of the Service for which the Customer purchases a subscription, Barracuda collects and maintains the security logs for a rolling 90-day period solely for Barracuda’s use to deliver the Service. These security logs are not available to Customer for download or through the XDR dashboard. The Service does not collect any end customer data other than security log data. Any information regarding the end customer in the dashboard will automatically be deleted when the Customer’s subscription expires. Barracuda will retain any security alerts for 15 months after a customer subscription expires.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- Other
- Other protection between networks
- Data is secured using TLS based encryption.
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
- Log and configuration data that is held in the Service is encrypted during transmission and at rest.
Availability and resilience
- Guaranteed availability
-
"Barracuda cloud solutions are built with high availability at the core to ensure uptime of services. Further details can be requested during purchase process.
Barracuda Networks supply a service with an SLA of 99.5%. See link for latest SLA documentation
https://assets.barracuda.com/assets/docs/dms/Barracuda_Managed_XDR_Service_Description.pdf" - Approach to resilience
- Available upon request
- Outage reporting
- All outages are recorded on website https://status.barracuda.com. Email and SMS alerts can be subscribed to for the relevant service
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Barracuda have a RBAC control system in place ensuring all administrators require authentication to modify or create policies and settings within the solution
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- Between 1 month and 6 months
- Access to supplier activity audit information
- You control when users can access audit information
- How long supplier audit data is stored for
- Between 1 month and 6 months
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- SOC 2 Type 2
- Information security policies and processes
- https://assets.barracuda.com/assets/docs/dms/Barracuda_Managed_XDR_Service_Description.pdf
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Barracuda has a comprehensive change control and QA process in place. Further details can be requested via https://trust.barracuda.com regarding inependent verification
- Vulnerability management type
- Undisclosed
- Vulnerability management approach
- Barracuda has a comprehensive vulnerability management process in place. Further details can be requested via https://trust.barracuda.com regarding inependent verification
- Protective monitoring type
- Undisclosed
- Protective monitoring approach
- Barracuda has a comprehensive proactive monitoring process in place. Further details can be requested via https://trust.barracuda.com regarding inependent verification
- Incident management type
- Undisclosed
- Incident management approach
- Barracuda has a comprehensive Incident management process in place. Further details can be requested via https://trust.barracuda.com regarding inependent verification
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 9f316d05-94ac-492e-9466-4e57b54bb49f
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Introducing transparency to pay and reward processes
- Working conditions which promote an inclusive working environment and promote retention and progression
-